vendor:
VU Web Visitor Analyst
by:
L0rd CrusAd3r
7,5
CVSS
HIGH
Authentication Bypass
287
CWE
Product Name: VU Web Visitor Analyst
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2010
VU Web Visitor Analyst Authentication Bypass
VU Web Visitor Analyst is an application that retrieves website visitors’ IP address, visited date and time, visited page name, their country, and their ISP. An authentication bypass vulnerability exists in the application, which allows an attacker to bypass authentication and gain access to the application.
Mitigation:
Ensure that authentication is properly implemented and enforced.